package com.example.demo.controller;

import org.apache.shiro.authz.annotation.Logical;
import org.apache.shiro.authz.annotation.RequiresRoles;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController;

import com.example.demo.common.BaseResult;

@RestController
@RequestMapping("/user")
public class UserController {

	@RequestMapping(value = "/getMessage", method = RequestMethod.GET)
	@RequiresRoles(logical = Logical.OR, value = {"user", "admin"})
	public BaseResult getMessage() {
		return new BaseResult(200, "您拥有用户权限，可以获得该接口的信息！", null);
	}
}
